First published: Fri Apr 12 2013(Updated: )
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/python-bugzilla | <0.9.0 | 0.9.0 |
Python Bugzilla Project Python-bugzilla | <=0.8.0 | |
Python Bugzilla Project Python-bugzilla | =0.6.0 | |
Python Bugzilla Project Python-bugzilla | =0.6.1 | |
Python Bugzilla Project Python-bugzilla | =0.6.2 | |
Python Bugzilla Project Python-bugzilla | =0.7.0 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
openSUSE openSUSE | =11.4 | |
openSUSE openSUSE | =12.2 | |
openSUSE openSUSE | =12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.